Light

Episode #1059 Quiz

MongoBleed
Date: 2026-01-06 | Length: 2.75 hrs | Episode page at twit.tv

About this episode

Security Now! Episode 1059 discusses the significant MongoBleed vulnerability (CVE-2025-14847) affecting all MongoDB versions since 3.6, allowing unauthenticated remote attackers to exfiltrate uninitialized server memory due to improper decompressed payload size validation in Zlib.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the primary security rationale given by the CA/Browser Forum for reducing the maximum lifetime of code signing certificates from 39 months to 15 months starting March 1, 2026?
Question 2: In the context of MongoBleed (CVE-2025-14847), what specific programming mistake in MongoDB's handling of compressed messages led to the vulnerability?
Question 3: Why does Smart App Control (SAC) in Windows 11 represent a significant change in user control over application trust?
Question 4: What security enhancement did the Python Package Index (PyPI) implement in 2025 to combat phishing attacks exploiting two-factor authentication (2FA)?
Question 5: According to the episode, what is the most significant policy failure that allowed MongoBleed to affect over 87,000 publicly reachable MongoDB instances?
Cancel